15 Total CVEs
15 AI Analyzed
0 CISA KEV
0 Critical

Profile

0% ended up actively exploited 0 of 15 added to CISA KEV
0% rated critical (CVSS 9.0+) 0 critical, 15 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

15 CVEs in the last 12 months

Products

  • Amazon Athena ODBC driver5
  • ion-java1
  • log4j-cve-2021-44228-hotpatch1
  • awslabs.dynamodb-mcp-server1
  • amazon-ssm-agent1
  • Amazon Redshift JDBC Driver1
  • Workspaces1
  • Kiro CLI1

11 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-85786
Analyzed
7.5
Amazon ion-java

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted c...

2026-09-06
Full analysis →
CVE-2026-85656
Analyzed
7.8
Amazon log4j-cve-2021-44228-hotpatch

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary...

2026-09-06
Full analysis →
CVE-2026-85654
Analyzed
7.8
Amazon awslabs.dynamodb-mcp-server

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might al...

2026-09-06
Full analysis →
CVE-2026-81849
Analyzed
8.8
Amazon amazon-ssm-agent

Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an aut...

2026-08-29
Full analysis →
CVE-2026-8178
Analyzed
8.1
Amazon Amazon Redshift JDBC Driver

An issue exists in Amazon Redshift JDBC Driver versions prior to 2

2026-05-09
Full analysis →
CVE-2026-7791
Analyzed
7.8
Amazon Workspaces

Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2

2026-05-05
Full analysis →
CVE-2026-5485
Analyzed
7.8
Amazon Amazon Athena ODBC driver

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2

2026-04-04
Full analysis →
CVE-2026-35562
Analyzed
7.5
Amazon Amazon Athena ODBC driver

Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2

2026-04-04
Full analysis →
CVE-2026-35561
Analyzed
7.4
Amazon Amazon Athena ODBC driver

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2

2026-04-04
Full analysis →
CVE-2026-35560
Analyzed
7.4
Amazon Amazon Athena ODBC driver

Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2

2026-04-04
Full analysis →
CVE-2026-35558
Analyzed
7.8
Amazon Amazon Athena ODBC driver

Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2

2026-04-04
Full analysis →
CVE-2025-12779
Analyzed
8.8
Amazon Amazon WorkSpaces

Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023

2025-11-06
Full analysis →